* CVE-2026-80794: nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
@ 2026-09-04 15:11 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-04 15:11 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
nci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each
parse a notification into an on-stack struct (nci_rf_discover_ntf /
nci_rf_intf_activated_ntf) that is not initialised. The RF
technology-specific parameters are only extracted when
rf_tech_specific_params_len is non-zero, so a notification that reports a
zero length leaves the rf_tech_specific_params union uninitialised - and
both handlers then pass it to nci_add_new_protocol(), which reads it:
- discover: nci_add_new_target() -> nci_add_new_protocol();
- activated: nci_target_auto_activated() -> nci_add_new_protocol().
nci_add_new_protocol() uses nfca_poll->nfcid1_len as both a branch
condition and a memcpy() length and copies nfcid1/sens_res/sel_res into
ndev->targets, which is later exposed to user space via NFC_CMD_GET_TARGET.
BUG: KMSAN: uninit-value in nci_add_new_protocol+0x624/0x6c0
nci_add_new_protocol+0x624/0x6c0
nci_ntf_packet+0x25b2/0x3c30
nci_rx_work+0x318/0x5d0
process_scheduled_works+0x84b/0x17a0
worker_thread+0xc10/0x11b0
kthread+0x376/0x500
Local variable ntf.i created at:
nci_ntf_packet+0xbc2/0x3c30
Zero-initialise both on-stack notifications so the union reads back as
zero when no technology-specific parameters are present.
The Linux kernel CVE team has assigned CVE-2026-80794 to this issue.
Affected and fixed versions
===========================
Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 5.10.269 with commit 1007a6b429d756513abd25bd00290908f2e89a4a
Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 5.15.218 with commit 4bda9ef8392710f21e99027467f3f4afdfb5c99a
Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 6.1.185 with commit fe69fed3495f676578d49414a069ad7d8468e2ce
Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 6.6.154 with commit 7489f59d1ea2d3298aa41de7baf193e5e6e132f6
Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 6.12.106 with commit 7086dab72b3ed95df96842801e10e935cfeb27a3
Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 6.18.47 with commit 0d4b5cfab6891a5ca0f6aef209beebba4bd7c095
Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 7.1.11 with commit 5bd00c0e1470d90d77a7c60242854257ddf14e00
Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 7.2.1 with commit d6f743d3d388913135681cde051c08823730194f
Issue introduced in 3.3 with commit e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20 and fixed in 7.3-rc1 with commit 8cbe06c1e699c0a165dae5093a2550e65f914818
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-80794
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
net/nfc/nci/ntf.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/1007a6b429d756513abd25bd00290908f2e89a4a
https://git.kernel.org/stable/c/4bda9ef8392710f21e99027467f3f4afdfb5c99a
https://git.kernel.org/stable/c/fe69fed3495f676578d49414a069ad7d8468e2ce
https://git.kernel.org/stable/c/7489f59d1ea2d3298aa41de7baf193e5e6e132f6
https://git.kernel.org/stable/c/7086dab72b3ed95df96842801e10e935cfeb27a3
https://git.kernel.org/stable/c/0d4b5cfab6891a5ca0f6aef209beebba4bd7c095
https://git.kernel.org/stable/c/5bd00c0e1470d90d77a7c60242854257ddf14e00
https://git.kernel.org/stable/c/d6f743d3d388913135681cde051c08823730194f
https://git.kernel.org/stable/c/8cbe06c1e699c0a165dae5093a2550e65f914818
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-04 15:20 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 15:11 CVE-2026-80794: nfc: nci: fix uninit-value in the RF discover/activated NTF handlers Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.